Monday, 8:47 a.m.
Three emails are waiting. One of them is a trap.
Coffee in hand, you open your inbox: a storage warning from IT, a note from the CEO, an all-staff maintenance notice. In the next ten minutes you'll learn to tell — at a glance — which one wants to hurt you.
Why This Email Matters
A phishing email isn't after your computer — it's after your credentials and your trust. And it only needs to work once.
What One Click Sets in Motion
This is the documented pattern of a real breach — walk through it.
- 08:49
The click
One employee opens the “quota” link. The page looks exactly like the company login.
- 08:50
Credentials harvested
The fake page silently forwards the typed password to the attacker — and redirects to the real site, so nothing feels wrong.
- 11:20
The account becomes the weapon
The attacker now mails the whole team from a real internal address. Every red flag you know disappears — except context.
- Day 3
Ransomware
Files encrypted across shared drives. Recovery is measured in weeks and six figures — all from one Monday-morning click.
Exhibit A: The Storage Warning
Here is the first email from your inbox, unedited. Read it the way an investigator would: the sender line, the tone of the message, where the button really points, and what arrived attached. You'll be asked to work on this exact email next.
Find the Red Flags
This is the first email from your inbox — the “storage warning” you just read as Exhibit A. It carries four red flags. Find each one by clicking directly on the email.
Flag 1 of 4: The display name says “Acme IT Support” — but something right next to it gives the game away. Click it.
Flag 2 of 4: Attackers need you to act before you think. Click the sentence built to do exactly that.
Flag 3 of 4: The button says “Verify Mailbox” — but where does it REALLY go? Click the true destination.
Flag 4 of 4: One more classic payload carrier is sitting in this email. Click it.
Same Layout, Different Intent
Email three is a maintenance notice from IT — and here's the uncomfortable truth: a clone of it would use the same logo, same layout, same signature. Drag the slider and find what CAN'T be faked.
The One Signal That Can't Be Faked
In both the storage warning and the IT clone, the logo, layout and tone were perfect. What was the reliable tell in BOTH cases?
The Four Flags, In Depth
You've now FOUND all four in the wild. Here's the pattern behind each, with the variant you'll meet next time.
Lookalike domains
acme-mail-services.net, acmе.com (that ‘е’ is Cyrillic) — read the part just before the last dot, every time. Display names are free text; domains are the identity.
Manufactured urgency
“24 hours”, “final notice”, “account suspended”. Real systems give you weeks and don't threaten. Pressure exists for one reason: to switch off the part of you doing this course.
Mismatched links
The text says portal.acme.com; the hover says acme-mail-quota-fix.com. On mobile, long-press to preview. When in doubt: don't travel through the link — go to the site yourself.
Unexpected attachments
Invoices you didn't expect, “voicemails” as .zip, reports nobody mentioned. The question is never “is this file safe” — it's “was this file expected”.
You've Spotted It. Now Don't Touch It.
Detection without the right response still ends in a breach story. The protocol is four verbs, in this order:
STOP — no clicks, no replies, no forwarding (forwarding delivers the bait to a colleague).
INSPECT — with your hands off, re-check the sender domain and the link's true target so your report says exactly what you saw.
REPORT — the report button isn't bureaucracy; it triggers removal of the same email from everyone else's inbox.
VERIFY — if it names a person or a vendor, contact them through a channel you already had, one that existed before this email arrived. The phone number inside the email belongs to the attacker.
Already clicked? Report anyway, immediately. Security teams reward fast honesty — the timeline you saw earlier is what silence buys.
Order the Response
The storage-warning email is still open on your screen. Put your next moves in order.
- Stop — hands off links, attachments and the reply button
- Re-check the sender domain and the link's true target
- Hit report — it protects every colleague who got the same email
- Verify with IT through the intranet or a known number
8:52 a.m. — Clear Your Inbox
Back to your Monday inbox. The storage scam is reported. Two emails remain — and a new one just arrived. Three decisions, three lives.
Email 2 — “from the CEO”: [email protected], subject Urgent - confidential: “Are you at your desk? I need gift cards for a client surprise. Keep this between us.”
- Correct. Executives don't route purchases through gift cards, don't demand secrecy, and don't mail from Gmail. This one script costs companies billions a year — you just declined your share.
- The three levers just worked on you: authority (CEO), urgency (now), secrecy (tell no one — i.e., let no one sanity-check this). A real executive request survives daylight.
Email 3 — the maintenance notice: the all-staff Saturday-maintenance announcement — the same one you compared against its clone on the slider a few minutes ago. Decide what to do with it.
- Correct — and this matters as much as catching the scams. Reporting everything buries the security team and dulls your own signal. Judgment, not paranoia.
- Understandable instinct, wrong call — this one has the real domain, expected context, and no request. The skill you're building is telling the difference, not fearing everything.
08:58 — new arrival: “DocuShare: Q3_Bonus_Structure.pdf shared with you” — from [email protected], requesting your company login to view the file.
- Correct — the bait is tuned (who wouldn't peek at bonus structures?), but the mechanic is naked: your company password has no business on a non-company domain. Ever.
- Curiosity is the payload here. One rule survives every disguise: company credentials go only into company domains.
docushare-files.comisn't one.
The Names Security Teams Use
Your reports this morning get triaged faster when they carry the right label. Flip each card.
Name What You Report
Precise names speed up the security team. Match each attack pattern to its term.
The Rule That Survives Every Disguise
If an email names a person or a vendor, verify through a ___ channel — never through contact details the email itself provides.
Your Morning, Scored
Here's how your Monday went:
Re-run “Find the Red Flags” with Exhibit A open beside you — the zones people miss under time pressure are the quiet ones.
Replay the inbox with the protocol screen in mind — for each email, ask what it wants you to DO and whether that request belongs in normal process.
Flip through the naming cards again, and re-read the VERIFY step of the protocol.
9:00 a.m. — Inbox Zero, Breach Zero
Thirteen minutes ago, three emails were waiting and one was a trap. You found four red flags on a live phish, told a clone from the real thing, and cleared an inbox without leaking a single credential.
Before you close this tab: find the report-phishing button in your real mail client — so on the Monday this actually happens, your hand already knows the way.